ayush1098 has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| Change Password of admin user | FirstBlood v3 | CRITICAL | Auth issues |
| Reflective XSS in appointment feature | FirstBlood v3 | Medium | Reflective XSS |
| Open redirect still works on logout.php | FirstBlood v3 | Low | Open Redirect |
| Reflected XSS at about.html | FirstBlood v3 | Medium | Reflective XSS |
| Refelcted XSS at doctors.php | FirstBlood v3 | Medium | Reflective XSS |
| Stored XSS on ambulance API | FirstBlood v3 | High | Stored XSS |
| Reflected XSS at id parameter | FirstBlood v3 | Medium | Reflective XSS |
| Stored XSS at meet_drs.pho | FirstBlood v3 | High | Stored XSS |
| Blind XSS in username field | FirstBlood v3 | CRITICAL | Stored XSS |
| Book non-bookable doctors in appointment | FirstBlood v3 | Low | Application/Business Logic |
| Change Docto's image | FirstBlood v3 | High | Stored XSS |